← Back

CVE-2020-16100

nvd nist
Published: Sep 15, 2020Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service's DCOM websocket thread due to improper shutdown of closed websocket connections, preventing it from accepting future DCOM websocket (Configuration Client) connections. Affected versions are v8.20 prior to v8.20.1166(MR3), v8.10 prior to v8.10.1211(MR5), v8.00 prior to v8.00.1228(MR6), all versions of 7.90 and earlier.

Affected (6)

1 product
Command Centre
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Gallagher
From 8.00 to 8.00.1228
From 8.10 to 8.10.1211
From 8.20 to 8.20.1166
Version 8.00.1228
Version 8.10.1211
Version 8.20.1166

References (2)

Source: disclosures@gallagher.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.